CVE-2024-7281: SourceCodester Lot Reservation Management System sql injection
A vulnerability classified as critical has been found in SourceCodester Lot Reservation Management System 1.0. Affected is an unknown function of the file /admin/index.php?page=managelot. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-273150 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability severity of CVE-2024-7281?
CVE-2024-7281 is classified as critical due to its potential for SQL injection attacks.
How can I fix CVE-2024-7281?
To fix CVE-2024-7281, ensure input validation and use prepared statements to prevent SQL injection in the affected file /admin/index.php.
Which versions of the software are affected by CVE-2024-7281?
CVE-2024-7281 affects version 1.0 of the Oretnom23 Lot Reservation Management System.
What type of injection vulnerability is associated with CVE-2024-7281?
CVE-2024-7281 is associated with SQL injection, allowing attackers to manipulate database queries.
How can attackers exploit CVE-2024-7281?
Attackers can exploit CVE-2024-7281 by manipulating the 'id' argument in the /admin/index.php?page=manage_lot endpoint.